Skip to content

Commit

Permalink
gcp: Allow GCB service agent for kubernetes-release-test
Browse files Browse the repository at this point in the history
Ref:
  - kubernetes/release#3729

Temporary allow the Service Agent for the GCB Service from project
`kubernetes-release-test`. This will enable artifacts release for
Kubernetes to a community-owned bucket.
  • Loading branch information
ameukam committed Sep 9, 2024
1 parent b426d46 commit f869fc9
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions infra/gcp/terraform/k8s-infra-releases-prod/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,14 @@ resource "google_storage_hmac_key" "fastly_reader_key" {
service_account_email = google_service_account.fastly_reader.email
}

// TODO: remove this after https://github.com/kubernetes/release/issues/3425
resource "google_storage_bucket_iam_member" "release_object_admin" {
bucket = module.k8s_releases_prod.bucket_name
role = "roles/storage.objectAdmin"
member = "serviceAccount:[email protected]"
depends_on = [module.k8s_releases_prod]
}

resource "google_storage_bucket_iam_member" "fastly_reader" {
bucket = module.k8s_releases_prod.bucket_name
role = "roles/storage.objectViewer"
Expand Down

0 comments on commit f869fc9

Please sign in to comment.